Legal
Security Policy
Last updated: July 6, 2026
Contents
1. Introduction
This Security Policy describes the technical, organizational, and administrative safeguards implemented by MyDirector AI Inc. (“MyDirector,” “we,” “us,” or “our”) to protect the confidentiality, integrity, and availability of systems and personal data processed through the Services.
MyDirector operates an AI-powered content creation platform that processes sensitive user inputs, including audio and video interview recordings, uploaded media, generated content, and data from connected third-party platforms. Given the nature of these Services, we are committed to maintaining a high standard of security across all layers of our infrastructure.
This Security Policy explains how MyDirector protects user data and systems from unauthorized access, misuse, alteration, or loss. It also describes the technical and organizational safeguards used to secure AI processing, media storage, and content workflows, while providing transparency into our security practices. The Policy supports compliance with applicable laws, including GDPR and relevant U.S. privacy laws, and outlines user responsibilities for maintaining account security. It works alongside our Privacy Policy and Terms of Service.
This Security Policy applies to all MyDirector systems, including web and mobile applications, AI interview and transcription systems, content creation and editing workflows, cloud infrastructure, APIs, third-party integrations, and internal tools used by staff and approved service providers. It covers all data processed through the Services, including account information, interview recordings, uploaded media, AI-generated content, analytics data, and social media integration data.
We apply layered security controls to protect data throughout its lifecycle. These include encryption in transit and at rest, strict role-based access controls, secure cloud infrastructure, continuous threat monitoring, regular security updates and patching, and contractual safeguards with third-party providers. We also design systems to isolate user data and prevent cross-account access.
While we implement strong security measures, no system is fully risk-free. Users are expected to help maintain security by protecting their credentials and managing access to connected accounts responsibly.
2. Security Infrastructure Overview
2.1 System Architecture Overview
The MyDirector platform operates on a modular, service-based architecture that separates core functions such as authentication, AI processing, media handling, and publishing workflows.
Key components include the frontend application layer for user interaction and content management, backend API layer handling authentication, requests, and business logic, AI processing layer for interviews, transcription, and content generation, media processing pipeline for video segmentation, editing, and rendering, integration layer for third-party platforms (social media APIs, AI providers), and storage layer for user data, media files, and generated outputs
This separation ensures that each component operates independently, improving both security isolation and system reliability.
2.2 Cloud Infrastructure
MyDirector relies on industry-standard cloud providers to ensure secure, scalable, and resilient infrastructure:
- Amazon Web Services (AWS): Used for core compute resources, secure storage, database hosting, and scalable backend infrastructure
- Vercel: Used for frontend deployment, edge delivery, and performance optimization across global regions
- Supabase: Used for authentication, database management (PostgreSQL), file storage, and real-time data synchronization
These providers implement strong physical, network, and application-level security controls, including encryption, redundancy across availability zones, and continuous infrastructure monitoring. All data stored within these systems is logically isolated per user account and protected using access control mechanisms and encrypted communication channels.
2.3 AI Processing Infrastructure
MyDirector uses a multi-provider AI architecture to securely power its interview, content creation, and media processing workflows. Interview media is securely routed through LiveKit, which manages real-time communication between MyDirector and authorized AI providers. OpenAI powers conversational AI interactions, interview assistance, conversation summarization, title generation, and onboarding transcription, while Deepgram performs real-time and batch speech-to-text transcription. Cartesia provides text-to-speech capabilities for AI voice interactions, Anthropic generates captions, persona profiles, interview questions, and content recommendations, and Memo securely maintains conversational context to improve continuity and personalization across interview sessions.
All communication between MyDirector and AI providers occurs via encrypted API connections with secure authentication. Each provider receives only the minimum information necessary to perform the requested functionality, and AI processing is isolated on a per-user and per-session basis to prevent unauthorized access or cross-account data exposure. AI-generated outputs and related processing data are securely returned to MyDirector for storage, editing, publishing, and ongoing content workflows, in accordance with our security controls and data protection practices.
2.4 Data Flow Architecture
MyDirector is designed to securely handle user data from input through processing, storage, and delivery. A typical flow includes: user submission of interviews or uploads, encrypted transmission via HTTPS, AI processing for transcription and content generation, optional human editorial review by authorized personnel, encrypted storage of final outputs, and secure publishing to connected platforms through APIs. System activity is continuously logged for security, debugging, and performance monitoring.
At every stage, encryption and access controls are applied to protect data from unauthorized access, alteration, or disclosure.
3. Data Protection and Encryption
All data transmitted between users and MyDirector is protected using Transport Layer Security (TLS). This includes HTTPS traffic, secure WebSocket connections for real-time AI interviews, encrypted backend and frontend communication, and secure API calls to third-party services, including AI providers, social platforms, and payment processors. We enforce TLS 1.2 or later to protect data in transit, ensuring that all sensitive actions, such as logins, uploads, and publishing, are transmitted securely.
All stored data is encrypted at rest using strong industry standards such as AES-256 or equivalent provided by our infrastructure partners. This applies to account information, authentication data, interview recordings, uploaded media, AI-generated outputs, analytics, and system backups. Encryption keys are securely managed through controlled systems and are never exposed directly to application-level services.
User media files, including video, audio, and images, are stored in private, access-controlled environments. Access is managed through signed, time-limited URLs and strict role-based permissions, with public exposure disabled by default. In addition, encryption keys and sensitive credentials are managed through secure key management systems with strict access controls, regular rotation, and availability limited to authorized system components.
4. Authentication and Account Security
We do not store user passwords in plain text. Instead, passwords are securely hashed using strong one-way cryptographic algorithms (such as bcrypt or equivalent standards) and salted to protect against common attacks, including rainbow table attacks. Password data is stored in secure database environments with strict access controls and is never accessible to employees or third-party service providers. Sensitive authentication data is also separated from application systems to reduce the risk of exposure.
We use secure session management to maintain authenticated access across the Services. This includes token-based authentication, secure cookie storage where applicable, automatic session expiration after inactivity, and session invalidation upon logout, password changes, or suspicious activity. Sessions may also be tracked across devices and browsers to help detect unusual behavior and strengthen account security.
We implement monitoring and controls to prevent unauthorized access and account abuse, including rate limiting, anomaly detection, IP-based monitoring, and alerts for unusual login activity, such as logins from new devices or locations. Repeated failed login attempts may trigger temporary account lockouts or additional verification requirements. In addition, multi-factor authentication (MFA) may be offered or required where available, using methods such as one-time passcodes or device-based verification. MFA adds an additional layer of protection, and users are encouraged to enable it, especially for accounts connected to social media integrations or sensitive content workflows.
5. Access Control and Internal Security
We use role-based access control (RBAC) to ensure system access is granted strictly based on job function and operational necessity. Access permissions are assigned based on defined roles, such as engineering, support, editorial, and infrastructure. Users only receive access to the systems and data required for their responsibilities, while administrative access is limited to authorized personnel. Sensitive data, including media files, interview recordings, and AI outputs, is separated by role, and access is reviewed whenever roles change or personnel leave.
Access to production systems and user data is restricted to vetted employees and approved contractors who require it to perform their duties. This includes background checks where appropriate, confidentiality obligations in contracts, time-limited or task-specific access for contractors, and immediate revocation of access upon termination. Access is also segmented to ensure that individuals interact only with the minimum data necessary for their work.
We apply the principle of least privilege across all systems, ensuring that all users and services have only the minimum access required to function. Elevated permissions are tightly controlled, time-limited, and logged, while sensitive production systems remain restricted to essential personnel. Default access settings are intentionally restrictive to reduce risk exposure across the platform.
We also maintain detailed internal logging and auditing of access to sensitive systems and data. This includes tracking access to user content, media files, AI-generated outputs, and administrative actions by employees and contractors. Audit logs are retained for security, compliance, and incident investigation purposes and are regularly reviewed to detect unusual or unauthorized activity.
6. AI Systems Security
MyDirector uses a secure, multi-provider AI architecture to support interview processing, transcription, content generation, and voice interactions. LiveKit securely routes real-time audio between MyDirector and authorized AI providers; OpenAI powers conversational AI interactions, summarization, title generation, and onboarding transcription; Deepgram performs live and batch speech-to-text transcription; Cartesia generates AI voice responses through text-to-speech; Anthropic generates captions, persona profiles, interview questions, and content recommendations; and Memo securely stores conversational context to provide continuity across interview sessions.
All communication with AI providers is encrypted in transit using secure API connections, and only the minimum data necessary to perform the requested task is transmitted. AI providers process information solely on MyDirector's behalf and are not permitted to access unrelated user data or information belonging to other accounts. AI processing activities are continuously monitored through logging and security controls to detect unauthorized access, misuse, or anomalous activity.
We require all AI providers to maintain industry-standard security practices, including encryption, access controls, secure infrastructure, and confidentiality obligations. Each provider performs a specific security role within the AI ecosystem:
| Provider | Security Role |
|---|---|
| Anthropic | Secure text generation and language processing |
| OpenAI | Conversational AI, summarization, and onboarding transcription |
| Deepgram | Secure speech-to-text transcription |
| Cartesia | Secure text-to-speech and voice synthesis |
| LiveKit | Secure real-time media routing and communication |
| Memo | Secure conversational memory and context management |
User data remains isolated throughout the AI processing lifecycle. LiveKit maintains separate real-time sessions for each user; Deepgram processes each interview independently; OpenAI and Anthropic receive isolated requests containing only the data required for the specific task; and Memo stores conversational memory separately for each user account to maintain continuity without exposing information across accounts. These controls help ensure that interview recordings, transcripts, generated content, and conversational context remain private, securely processed, and inaccessible to unauthorized users or other customer accounts.
7. Media and Content Security
MyDirector implements strong security controls to protect all user media, including video, audio, images, and AI-generated outputs, throughout their lifecycle on the platform. This includes secure storage, controlled access, and protected processing environments designed to reduce exposure risk and prevent unauthorized access.
All uploaded and generated media files are stored in encrypted, access-controlled cloud storage. Storage systems are configured with private-by-default settings, strict separation between environments, and no public access unless explicitly enabled by the user. Media used in AI processing or editing workflows is handled securely and retained only as long as necessary to provide the Services, subject to retention rules and account status.
We use signed, time-limited URLs to control access to media files. These links expire automatically and cannot be reused once invalidated. Access is protected by authentication checks, role-based permissions, and revocation mechanisms that apply when files are deleted, permissions change, or access is no longer required. Internal access is also restricted and limited to authorized personnel only.
User content is processed through secure, staged pipelines that handle ingestion, AI transcription, segmentation, editing, and output generation. At every stage, data is encrypted in transit and processed in isolated environments. AI-generated outputs are treated as private user data, stored securely, tied to the originating account, and protected from cross-user access or reuse. These outputs are only accessed internally when necessary for support, maintenance, or quality assurance, and are never publicly exposed unless the user explicitly chooses to publish them.
9. Logging, Monitoring, and Threat Detection
MyDirector implements comprehensive logging, monitoring, and threat detection systems designed to maintain platform security, ensure operational stability, and quickly identify unauthorized access, abuse, or system anomalies. These systems support incident response, fraud prevention, performance optimization, and compliance with applicable security standards across both our platform and AI-powered services.
We maintain structured logs across core system components, including API requests and responses, authentication events, media uploads, publishing actions, administrative activities, and AI processing workflows. MyDirector also maintains audit logs for requests made to AI providers, including OpenAI, Anthropic, Deepgram, Cartesia, LiveKit, and Memo. These logs are used to monitor system health, troubleshoot processing failures, detect abuse, investigate security incidents, and support operational reliability while minimizing the amount of personal information retained. All logs are protected by strict access controls and retained only as long as necessary for security, operational, and legal purposes.
We use automated and manual monitoring tools to detect and respond to security risks in real time. This includes infrastructure and application performance monitoring, security event detection, AI service health monitoring, rate limiting to prevent abuse, and third-party alerting systems. These controls help identify unusual behavior, reduce downtime, maintain service reliability, and quickly detect issues affecting AI processing pipelines or platform operations.
We also implement fraud and abuse detection mechanisms to identify suspicious activity, including abnormal login patterns, excessive API usage, bot activity, attempts to bypass security controls, and unusual AI processing behavior. Our systems continuously analyze security signals from platform activity, AI service interactions, authentication systems, and infrastructure providers. When potential incidents are detected, they are escalated through our incident response procedures for investigation, containment, and remediation, and affected users or regulatory authorities may be notified where required by applicable law.
10. Data Isolation and Multi-Tenancy Security
MyDirector uses a multi-tenant architecture to ensure that each user’s data is fully isolated within a secure logical boundary. Every account is assigned a unique tenant identifier, and all user data, including AI interview outputs, media files, transcripts, and analytics, is logically separated across system services. Each request is scoped to the authenticated tenant, ensuring that users interact only with their own data.
We enforce strict cross-account access prevention measures so that no user, employee, or system process can access another user’s data unless explicitly authorized for support, security, or legal reasons. This includes authorization checks on every request, secure session validation, and enforced access boundaries at both application and API levels. Internal administrative access is tightly restricted, logged, and limited to approved scenarios only.
At the database level, we implement additional security controls to reinforce tenant isolation. These include row-level security policies, encrypted storage for sensitive data, strict access restrictions limiting database queries to authorized services, and segmented data schemas where applicable. We also maintain audit logs and regularly review database permissions to ensure that all data remains securely isolated and accessible only through approved application logic.
11. Backup and Disaster Recovery
We implement automated backup systems across key parts of the platform to ensure continuous protection of user data. This includes scheduled database backups, regular snapshots of media storage systems, incremental backups to capture ongoing changes, and versioned backups that allow restoration to specific points in time where supported. Backup processes run without interrupting platform performance and are continuously monitored for completion and integrity.
We maintain structured data recovery procedures to restore services in the event of system failure, corruption, or data loss. These procedures include restoring databases from verified backups, recovering media files and AI-generated content from secure storage, and executing step-by-step recovery workflows for core services such as authentication, AI processing, and content access. Recovery processes are regularly tested to ensure reliability and to minimize downtime and data loss.
To improve resilience, MyDirector employs system redundancy and failover mechanisms throughout its critical infrastructure. This includes multi-zone or multi-region deployments, redundant databases and storage systems, load balancing across services, and automatic failover to backup systems when failures occur. These measures help ensure continued availability of the Services even during unexpected outages or infrastructure disruptions.
All backups are secured using strong encryption both in transit and at rest, with strict access controls limiting access to authorized personnel only. Backup environments are isolated from production systems and hosted within secure cloud infrastructure. We also monitor backup integrity, enforce lifecycle management policies, and ensure controlled deletion of outdated backups. Backup data is protected with the same level of security as live production data, ensuring confidentiality and integrity at all times.
12. Vulnerability Management
MyDirector maintains a continuous vulnerability management program to identify, assess, and remediate security risks across systems, dependencies, and infrastructure. This program is designed to reduce exposure to known threats and ensure that the platform remains secure, stable, and up to date.
We implement structured security patch management across all systems, including operating systems, frameworks, and cloud infrastructure. Security patches from vendors are reviewed and applied in a timely manner, with priority given to critical and high-severity vulnerabilities. Updates are deployed during controlled maintenance windows, and we continuously monitor vendor advisories to ensure emerging risks are addressed quickly.
We also perform ongoing dependency scanning and management for all third-party libraries and components used in the platform. Automated tools are used to detect known vulnerabilities, outdated packages, or insecure dependencies. These are regularly updated, replaced, or removed as necessary, supported by monitoring CVE databases and open-source security advisories to prevent external components from introducing risk to the system.
Where appropriate, MyDirector conducts penetration testing and security assessments, either internally or through qualified third-party security professionals. These tests may simulate real-world attacks to evaluate application security, API protections, authentication controls, and infrastructure configuration. In addition, we maintain a responsible disclosure program that allows security researchers and users to report vulnerabilities in good faith, which are then reviewed, investigated, and remediated with appropriate confidentiality and corrective action.
13. Incident Response and Breach Management
We use a combination of automated monitoring systems and manual oversight to detect potential security incidents in real time. This includes continuous monitoring of system logs, API activity, authentication events, infrastructure alerts, and third-party integrations. We also track unusual behavior such as abnormal login attempts, unexpected traffic patterns, system errors, and other security signals. Any potential incident is immediately flagged for review by our security or engineering teams.
When a security incident is identified, we take immediate steps to contain and reduce potential impact. This may include isolating affected systems, revoking or rotating compromised credentials, blocking suspicious activity, disabling affected features, or applying emergency patches. We also preserve relevant data for forensic analysis to understand the cause and prevent recurrence, while prioritizing the protection of user data and system integrity.
We maintain a structured internal escalation process to ensure incidents are handled efficiently and by the appropriate teams. Critical issues are escalated immediately to security and engineering leadership, with clear coordination across infrastructure, product, and support teams. All incidents are documented, including response actions and resolution steps, and significant incidents undergo post-incident review to identify root causes and improve future defenses.
Where required by law or where an incident poses a material risk, we notify affected users and relevant regulatory authorities within applicable timeframes. Notifications may include details of the incident, its potential impact, steps users can take to protect their accounts, and actions MyDirector has taken to resolve the issue. We aim to remain transparent while ensuring that ongoing investigations and system security are not compromised.
14. Third-Party Security and Subprocessors
MyDirector relies on carefully selected third-party service providers (“Subprocessors”) to support artificial intelligence, cloud infrastructure, storage, communications, payments, and other core platform services. Before engaging any Subprocessor, we assess its security posture and require appropriate technical, organizational, and contractual safeguards to protect personal information and maintain the security of the Services.
Our artificial intelligence infrastructure consists of trusted providers, each performing a specific function within the platform. Anthropic is used for secure text generation, including captions, persona creation, interview questions, and content recommendations. OpenAI powers conversational AI interactions, interview assistance, summarization, title generation, and onboarding transcription. Deepgram securely processes live and recorded interview audio for speech-to-text transcription, while Cartesia provides text-to-speech capabilities for AI voice interactions. LiveKit securely routes real-time audio and media between MyDirector and our AI providers, and Memo securely maintains conversational memory and context to improve continuity across interview sessions.
All communications between MyDirector and these AI providers occur via encrypted API connections with secure authentication. Each provider receives only the minimum information necessary to perform the requested functionality and processes data solely in accordance with MyDirector's documented instructions. Our agreements require AI providers to implement industry-standard encryption, secure infrastructure, access controls, security monitoring, confidentiality protections, and applicable data protection measures. They are contractually prohibited from using MyDirector customer data for advertising, profiling, or training publicly available AI models unless expressly authorized by MyDirector and permitted by applicable law.
In addition to our AI providers, we rely on trusted cloud infrastructure providers such as Amazon Web Services (AWS), Supabase, and Vercel for secure hosting, storage, databases, networking, and application delivery. We also use third-party payment processors to securely handle subscription billing and payment transactions in accordance with PCI DSS requirements. All Subprocessors are subject to contractual security obligations, including confidentiality commitments, breach notification requirements, security controls, and restrictions on the use of personal information. We periodically review our Subprocessors to ensure they continue to meet our security expectations and may update them as our technology stack evolves, with notice provided where required by applicable law.
15. User Security Responsibilities
Users are responsible for maintaining the security of their accounts and ensuring that access credentials and connected systems are properly protected. This includes keeping account information accurate and up to date, ensuring that only authorized individuals access the account, logging out of the Services on shared or public devices, and promptly updating account details if suspicious activity is detected. Users are also responsible for all activity conducted through their account, unless otherwise required by applicable law.
Users must take appropriate steps to protect login credentials and authentication methods. This includes using strong, unique passwords; keeping passwords and authentication tokens confidential; avoiding credential sharing with third parties; and using secure devices and networks when accessing the Services. If a compromise is suspected, passwords should be changed immediately. MyDirector will never request passwords through unsecured channels.
Where users connect third-party platforms such as Instagram, YouTube, TikTok, or LinkedIn, they are responsible for managing the security and permissions of those integrations. This includes ensuring proper authorization, reviewing OAuth permissions, monitoring account activity on connected platforms, and revoking access when no longer needed. Users are also responsible for complying with each third-party platform’s terms and security requirements.
Users are encouraged to promptly report any suspected security issues, unauthorized access, or unusual activity affecting their account or the Services. Reports should include relevant details, such as a description of the issue, affected features, timestamps, and any available supporting information. We will investigate all reports and take appropriate action, which may include containment, remediation, and user notification where required.
16. Compliance and Security Standards
MyDirector applies security and privacy practices designed to align with key regulatory frameworks, including GDPR for EEA users and CCPA/CPRA for California residents. These measures include encryption of personal data, access controls, data minimization, secure Subprocessors, and safeguards for international data transfers. We continuously review our systems to ensure ongoing compliance with applicable legal requirements as the Services evolve.
For California residents, we implement protections that restrict unauthorized access to or misuse of personal data and support user rights, such as access, deletion, correction, and opt-out requests, where applicable. We maintain internal controls to prevent misuse of personal information and ensure data is used only for disclosed and legitimate business purposes. We do not sell personal information.
Our security program is designed to align with SOC 2 Trust Services Criteria, covering security, availability, confidentiality, and privacy. This includes role-based access controls, system logging and monitoring, secure development practices, vendor risk management, encryption, and incident response procedures. While formal certification may not always be in place, our controls are designed to meet SOC 2 expectations as the platform scales.
Security at MyDirector is continuously improved as threats, technologies, and regulations evolve. We regularly update infrastructure, patch vulnerabilities, improve encryption and authentication systems, enhance monitoring and detection, review Subprocessors, and conduct internal security assessments. We may update or strengthen our security practices at any time to maintain the protection of user data and system integrity.
8. Social Media Integration Security
MyDirector integrates with third-party social media platforms to enable users to publish, schedule, and manage content, and to retrieve analytics and performance data. These integrations are secured using industry-standard authentication protocols and strict access controls designed to protect user accounts and prevent unauthorized access. We do not store social media passwords; instead, access is granted through secure authorization flows and platform-controlled token-based permissions.
We use OAuth 2.0 (or equivalent authorization frameworks provided by each platform) to securely connect user accounts. This process involves redirecting users to official third-party authorization pages, obtaining consent for specific permissions, and exchanging temporary authorization codes for secure access tokens. No passwords are stored or handled by MyDirector, and all permissions are defined by platform-specific scopes that determine which data can be accessed and which actions can be performed.
Access tokens and refresh tokens are securely stored using encryption and are kept within restricted backend environments only. These credentials are never exposed to frontend systems or unauthorized services. Token usage is limited to necessary backend functions such as publishing content, retrieving analytics, or managing integrations. Tokens are also regularly validated, refreshed, and expired in accordance with third-party platform policies to maintain security.
Users control which permissions they grant, and we request only the minimum access required for the requested functionality, such as posting, analytics, or scheduling. These permissions are scoped and regularly reviewed to ensure least-privilege access. Users may revoke access to any connected platform at any time through either the MyDirector interface or the third-party platform’s security settings. Once revoked, we immediately stop accessing new data, invalidate stored tokens where possible, and disable related functionality, while retaining only the historical data necessary for legal, compliance, or auditing purposes.